Description
Missing Authorization vulnerability in shiptime ShipTime: Discounted Shipping Rates shiptime-discount-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShipTime: Discounted Shipping Rates: from n/a through <= 1.1.1.
Published: 2026-04-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access
Action: Apply Patch
AI Analysis

Impact

The plugin contains a missing authorization flaw that allows any user who can reach the website to invoke functionality intended for privileged users. This flaw is a classic missing authorization issue (CWE-862). Exploiting it can let an attacker read or modify shipping configuration data, potentially altering shipping rates or accessing customer orders. The compromise could lead to financial loss and customer data exposure.

Affected Systems

The issue affects WordPress sites running the ShipTime: Discounted Shipping Rates plugin version 1.1.1 and earlier. The plugin is maintained by the vendor ShipTime. Sites that have not applied the latest release (greater than 1.1.1) are susceptible. The vulnerability description lists affected versions up to 1.1.1.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score below 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog, implying no well‑known public exploits have been documented. An attacker would need to reach the plugin’s endpoints, which can be achieved remotely via HTTP, but no authentication is required, making the attack relatively straightforward once the site is accessible. Overall, the risk is moderate but the low exploitation probability suggests that the threat is low unless the site is particularly valuable or the attacker is highly motivated.

Generated by OpenCVE AI on April 8, 2026 at 21:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the ShipTime: Discounted Shipping Rates plugin to the latest version (greater than 1.1.1).
  • Verify that no older plugin files remain on the server.
  • Scan access logs for suspicious activity.
  • If an update is not immediately possible, disable or remove the plugin until a patch is applied to prevent unauthorized use.

Generated by OpenCVE AI on April 8, 2026 at 21:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Wed, 08 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Shiptime
Shiptime shiptime: Discounted Shipping Rates
Wordpress
Wordpress wordpress
Vendors & Products Shiptime
Shiptime shiptime: Discounted Shipping Rates
Wordpress
Wordpress wordpress

Wed, 08 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in shiptime ShipTime: Discounted Shipping Rates shiptime-discount-shipping allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ShipTime: Discounted Shipping Rates: from n/a through <= 1.1.1.
Title WordPress ShipTime: Discounted Shipping Rates plugin <= 1.1.1 - Broken Access Control vulnerability
Weaknesses CWE-862
References

Subscriptions

Shiptime Shiptime: Discounted Shipping Rates
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:52:04.052Z

Reserved: 2026-04-07T10:57:59.671Z

Link: CVE-2026-39672

cve-icon Vulnrichment

Updated: 2026-04-08T19:15:41.346Z

cve-icon NVD

Status : Deferred

Published: 2026-04-08T09:16:38.687

Modified: 2026-04-29T10:17:38.590

Link: CVE-2026-39672

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:28:09Z

Weaknesses